Live data from Hacker News

Disclosure of three 0-day iOS vulnerabilities

habr.com

101–110 of 464 posts

Re: Disclosure of three 0-day iOS vulnerabilities

#101

It must be nice to give up $100k by being impatient. I do understand that OP probably feels a moral reason to do so, but that $100k would be life-changing for me, even if it took 3 years to pay out.

There is no $100K coming. Apple hopes you'll stay silent by dangling a hypothetical $100K (or whatever large amount) in the vague future. Once they've fixed the bug, they no longer have an incentive to pay you so they won't.

Seems more likely it'll just take 3-4 years with months of silence at a time, based on the extremely few security Radars I've ever filed as a developer. 90 days to publication is certainly a valid choice, but it's also a personal choice that reduces a probable $100k payment in X years to a certain $0 payment today. I would be fine with that delay. OP is not, and that's fine too. I don't know whether that's an acceptable choice or not to anyone else, but Apple should be disclosing their communication practices a lot more clearly here. I discourage participation by anyone who isn't willing to wait a year between replies.

Re: Disclosure of three 0-day iOS vulnerabilities

#102
post #57
post #40

Earlier quoted context omitted.

Settings > Cellular It shows my carrier, amount of data used and shows remaining on my plan. Mine reads, Usage: Used 7.43GB - Unlimited If I click on it it has 3 fields. Data, Calls, Messages Data reads the same here. Calls and Messages simply say ‘Unlimited’

My phone does not have this (iPhone on 15.0 in the US, AT&T).

Mine doesn't have this either (Europe), and I have unlimited data too. I have a "Data Plan" setting under "Mobile Data", which is not activated, so I'm guessing that setting is only there if your provider gives you a data plan that Apple recognises.

Re: Disclosure of three 0-day iOS vulnerabilities

#103

Earlier quoted context omitted.

God, I would HATE if the US follows the EU with this craziness. I'm already sick of the cookie popups, now layer on the GDPR insanity and we will definitely lose the privacy fight to users who will be sick of this nonsense as well. I've seen studies that show crap like GDPR (which makes basically all normal interaction cumbersome) has like 10% of folks clicking around to "opt-out" while 90% can't be bothered. And of…

GDPR cookie consent banners that make it more difficult to opt out than opt in are illegal, and only continue to exist because the GDPR is poorly and inconsistently enforced.

That's the point. GDPR without good enforcement is useless and meaningless. I'd even argue that all this time since GDPR and until something is done about enforcement if ever (that is not just a random fine, which is considered cost of doing business) all that GDPR is doing is allowing these companies to come up with more elaborate ways to scam (I'm looking at whoever the assholes who work, run, or are remotely involved with trustarc.com).

Re: Disclosure of three 0-day iOS vulnerabilities

#104

Earlier quoted context omitted.

Cybersecurity is a genuinely hard problem, but stuff like this is dropping the ball entirely. It's not hard to solve exploits like faulty permission-checking after they've been reported to you. Sure, there are always going to be problems you miss. I can forgive them shipping with zero-days, it happens. Failing to respond to reports is just that: failing.

It really helps add some color to the motivations behind notorization. It seems ridiculous to me that I have to jump through so many hoops to run an executable that I trust. Especially when Apple can’t be bothered to follow up on real vulnerabilities that have already been reported.

Exactly - any PR propaganda about notorization or signing making it safer for users is just BS. It's a gate-keeping mechanism that adds a layer of power to apple and prevent any control of the app market from slipping away.

Re: Disclosure of three 0-day iOS vulnerabilities

#105
As bad as this is for people who use iOS, I think it's good in the long run.

People here are getting boggled down in details about how is it possible for this to happen and what sort of policies apple has internally for it to be possible, but that doesn't really matter. Any company even 10% the size of APple should not be given the benefit of the doubt because obviously they'd all prefer not to have the major/minor embarrassment, if they can. Bounty programs exist not because they care about security of their customers only, but it's also a way to promote the company as security-conscious and avoid having 0days sold on the black market.

But to overcome this you can just continue publishing 0-days straight to the public. Put really easy to use sourcecode on github/bucket/srht/etc... allowing script-kiddies and copy-pasters to make use of them easily. This will either drive people to lose trust or force Apple to scramble to release fixes, either way it will push them to respect researchers and fix their bounty program or setup better security guidelines in general.

Props to the author for following through and releasing.

Re: Disclosure of three 0-day iOS vulnerabilities

#106
post #104

Earlier quoted context omitted.

It really helps add some color to the motivations behind notorization. It seems ridiculous to me that I have to jump through so many hoops to run an executable that I trust. Especially when Apple can’t be bothered to follow up on real vulnerabilities that have already been reported.

Exactly - any PR propaganda about notorization or signing making it safer for users is just BS. It's a gate-keeping mechanism that adds a layer of power to apple and prevent any control of the app market from slipping away.

Along with a solid bit of resume building for SecEng, I'd say yeah exactly that.

Re: Disclosure of three 0-day iOS vulnerabilities

#107
Why anyone at Apple decided that it was acceptable to log medical data in such an unsafe way?

I currently work in an IT health care company in Europe, and we must alway store the data fully encrypted with strict access control. We even decided to not make sure to not persist any medical data on user devices to not take unnecessary risks. And there, Apple logs everything on the iPhone? Why?

Re: Disclosure of three 0-day iOS vulnerabilities

#108

Earlier quoted context omitted.

God, I would HATE if the US follows the EU with this craziness. I'm already sick of the cookie popups, now layer on the GDPR insanity and we will definitely lose the privacy fight to users who will be sick of this nonsense as well. I've seen studies that show crap like GDPR (which makes basically all normal interaction cumbersome) has like 10% of folks clicking around to "opt-out" while 90% can't be bothered. And of…

GDPR cookie consent banners that make it more difficult to opt out than opt in are illegal, and only continue to exist because the GDPR is poorly and inconsistently enforced.

Cookie consent banners have nothing to do with GDPR, but with the ePrivacy directive. GDPR clarifies what is "consent", but this is not what leaded to the proliferation of cookie banners.

Please note if you have strictly necessary cookies, you don't need to have cookie banners, and if your cookies are anonymous, you don't need them either !

The proliferation of cookie banners just means that people running such websites are usually terrible with regards to consent, personally identifiable information, and so on.

Re: Disclosure of three 0-day iOS vulnerabilities

#109

I really hate the path Apple is taking. They make excellent products, really the average Joe simply loves Apple products. But they need to stop acting anti-consumer and anti-developer to “protect” their IP. At this point they could release the schematics of iPhone 13 and still people will buy Apple’s iPhone than someone who copied them. Rant over.

Actually, these vulnerabilities are good evidence that Apple does not make excellent products.

Re: Disclosure of three 0-day iOS vulnerabilities

#110
One more reason why "closed systems" are not magically superior. Closed systems still have vulnerability, and the culture that creates and maintains the closed system shuns those that find flaws in it. So much so that security researcher becomes, in their minds and practices, synonymous with black hat actors. Why would you report vulns to a company that doesn't want it? Go sell it elsewhere and use that money to get a better device. Yet researchers persist, for the good of secure technology.
Post reply on HN